{
"id": "ISO/IEC 27701:2025",
"name": "ISO 27701 (2025)",
"logo": {
"light": "",
"dark": ""
},
"controls": [
{
"id": "4.1",
"name": "Context of the organization - Understanding the organization and its context"
},
{
"id": "4.2",
"name": "Context of the organization - Understanding the needs and expectations of interested parties"
},
{
"id": "4.3",
"name": "Context of the organization - Determining the scope of the privacy information management system"
},
{
"id": "4.4",
"name": "Context of the organization - Privacy information management system"
},
{
"id": "5.1",
"name": "Leadership - Leadership and commitment"
},
{
"id": "5.2",
"name": "Leadership - Privacy Policy"
},
{
"id": "5.3",
"name": "Leadership - Roles, responsibilities and authorities"
},
{
"id": "6.1.1",
"name": "Planning - General actions to address risks and opportunities"
},
{
"id": "6.1.2",
"name": "Planning - Privacy risk assessment"
},
{
"id": "6.1.3",
"name": "Planning - Privacy risk treatment"
},
{
"id": "6.2",
"name": "Planning - Privacy objectives and planning to achieve them"
},
{
"id": "6.3",
"name": "Planning - Planning of changes"
},
{
"id": "7.1",
"name": "Support - Resources"
},
{
"id": "7.2",
"name": "Support - Competence"
},
{
"id": "7.3",
"name": "Support - Awareness"
},
{
"id": "7.4",
"name": "Support - Communication"
},
{
"id": "7.5.1",
"name": "Support - Documented information - General"
},
{
"id": "7.5.2",
"name": "Support - Documented information - Creating and updating documented information"
},
{
"id": "7.5.3",
"name": "Support - Documented information - Control of documented information"
},
{
"id": "8.1",
"name": "Operation - Operational planning and control"
},
{
"id": "8.2",
"name": "Operation - Privacy risk assessment"
},
{
"id": "8.3",
"name": "Operation - Privacy risk treatment"
},
{
"id": "9.1",
"name": "Performance evaluation - Monitoring, measurement, analysis and evaluation"
},
{
"id": "9.2.1",
"name": "Performance evaluation - Internal audit - General"
},
{
"id": "9.2.2",
"name": "Performance evaluation - Internal audit - Internal audit programme"
},
{
"id": "9.3.1",
"name": "Performance evaluation - Management review - General"
},
{
"id": "9.3.2",
"name": "Performance evaluation - Management review - Management review inputs"
},
{
"id": "9.3.3",
"name": "Performance evaluation - Management review - Management review results"
},
{
"id": "10.1",
"name": "Improvement - Continual improvement"
},
{
"id": "10.2",
"name": "Improvement - Nonconformity and corrective action"
},
{
"id": "A.1.2.2",
"name": "Conditions for collection and processing - Identify and document purpose"
},
{
"id": "A.1.2.3",
"name": "Conditions for collection and processing - Identify lawful basis"
},
{
"id": "A.1.2.4",
"name": "Conditions for collection and processing - Determine when and how consent is to be obtained"
},
{
"id": "A.1.2.5",
"name": "Conditions for collection and processing - Obtain and record consent"
},
{
"id": "A.1.2.6",
"name": "Conditions for collection and processing - Privacy impact assessment"
},
{
"id": "A.1.2.7",
"name": "Conditions for collection and processing - Contracts with PII processors"
},
{
"id": "A.1.2.8",
"name": "Conditions for collection and processing - Joint PII controller"
},
{
"id": "A.1.2.9",
"name": "Conditions for collection and processing - Records related to processing PII"
},
{
"id": "A.1.3.2",
"name": "Obligations to PII principals - Determining and fulfilling obligations to PII principals"
},
{
"id": "A.1.3.3",
"name": "Obligations to PII principals - Determining information for PII principals"
},
{
"id": "A.1.3.4",
"name": "Obligations to PII principals - Providing information to PII principals"
},
{
"id": "A.1.3.5",
"name": "Obligations to PII principals - Providing mechanism to modify or withdraw consent"
},
{
"id": "A.1.3.6",
"name": "Obligations to PII principals - Providing mechanism to object to PII processing"
},
{
"id": "A.1.3.7",
"name": "Obligations to PII principals - Access, correction or erasure"
},
{
"id": "A.1.3.8",
"name": "Obligations to PII principals - PII controllers' obligations to inform third parties"
},
{
"id": "A.1.3.9",
"name": "Obligations to PII principals - Providing copy of PII processed"
},
{
"id": "A.1.3.10",
"name": "Obligations to PII principals - Handling requests"
},
{
"id": "A.1.3.11",
"name": "Obligations to PII principals - Automated decision making"
},
{
"id": "A.1.4.2",
"name": "Privacy by design and privacy by default - Limit collection"
},
{
"id": "A.1.4.3",
"name": "Privacy by design and privacy by default - Limit processing"
},
{
"id": "A.1.4.4",
"name": "Privacy by design and privacy by default - Accuracy and quality"
},
{
"id": "A.1.4.5",
"name": "Privacy by design and privacy by default - PII minimization objectives"
},
{
"id": "A.1.4.6",
"name": "Privacy by design and privacy by default - PII de-identification and deletion at the end of processing"
},
{
"id": "A.1.4.7",
"name": "Privacy by design and privacy by default - Temporary files"
},
{
"id": "A.1.4.8",
"name": "Privacy by design and privacy by default - Retention"
},
{
"id": "A.1.4.9",
"name": "Privacy by design and privacy by default - Disposal"
},
{
"id": "A.1.4.10",
"name": "Privacy by design and privacy by default - PII transmission controls"
},
{
"id": "A.1.5.2",
"name": "PII sharing, transfer and disclosure - Identify basis for PII transfer between jurisdictions"
},
{
"id": "A.1.5.3",
"name": "PII sharing, transfer and disclosure - Countries and international organizations to which PII can be transferred"
},
{
"id": "A.1.5.4",
"name": "PII sharing, transfer and disclosure - Records of transfer of PII"
},
{
"id": "A.1.5.5",
"name": "PII sharing, transfer and disclosure - Records of PII disclosures to third parties"
},
{
"id": "A.2.2.2",
"name": "Conditions for collection and processing - Customer agreement"
},
{
"id": "A.2.2.3",
"name": "Conditions for collection and processing - Organization's purposes"
},
{
"id": "A.2.2.4",
"name": "Conditions for collection and processing - Marketing and advertising use"
},
{
"id": "A.2.2.5",
"name": "Conditions for collection and processing - Infringing instruction"
},
{
"id": "A.2.2.6",
"name": "Conditions for collection and processing - Customer obligations"
},
{
"id": "A.2.2.7",
"name": "Conditions for collection and processing - Records related to processing PII"
},
{
"id": "A.2.3.2",
"name": "Obligations to PII principals - Comply with obligations to PII principals"
},
{
"id": "A.2.4.2",
"name": "Privacy by design and privacy by default - Temporary files"
},
{
"id": "A.2.4.3",
"name": "Privacy by design and privacy by default - Return, transfer or disposal of PII"
},
{
"id": "A.2.4.4",
"name": "Privacy by design and privacy by default - PII transmission controls"
},
{
"id": "A.2.5.2",
"name": "PII sharing, transfer and disclosure - Basis for PII transfer between jurisdictions"
},
{
"id": "A.2.5.3",
"name": "PII sharing, transfer and disclosure - Countries and international organizations to which PII can be transferred"
},
{
"id": "A.2.5.4",
"name": "PII sharing, transfer and disclosure - Records of PII disclosures to third parties"
},
{
"id": "A.2.5.5",
"name": "PII sharing, transfer and disclosure - Notification of PII disclosure requests"
},
{
"id": "A.2.5.6",
"name": "PII sharing, transfer and disclosure - Legally binding PII disclosures"
},
{
"id": "A.2.5.7",
"name": "PII sharing, transfer and disclosure - Disclosure of subcontractors used to process PII"
},
{
"id": "A.2.5.8",
"name": "PII sharing, transfer and disclosure - Engagement of a subcontractor to process PII"
},
{
"id": "A.2.5.9",
"name": "PII sharing, transfer and disclosure - Change of subcontractor to process PII"
},
{
"id": "A.3.3",
"name": "Information security - Policies for information security"
},
{
"id": "A.3.4",
"name": "Information security - Information security roles and responsibilities"
},
{
"id": "A.3.5",
"name": "Information security - Classification of information"
},
{
"id": "A.3.6",
"name": "Information security - Labelling of information"
},
{
"id": "A.3.7",
"name": "Information security - Information transfer"
},
{
"id": "A.3.8",
"name": "Information security - Identity management"
},
{
"id": "A.3.9",
"name": "Information security - Access rights"
},
{
"id": "A.3.10",
"name": "Information security - Addressing information security within supplier agreements"
},
{
"id": "A.3.11",
"name": "Information security - Information security incident management planning and preparation"
},
{
"id": "A.3.12",
"name": "Information security - Response to information security incidents"
},
{
"id": "A.3.13",
"name": "Information security - Legal, statutory, regulatory and contractual requirements"
},
{
"id": "A.3.14",
"name": "Information security - Protection of records"
},
{
"id": "A.3.15",
"name": "Information security - Independent review of information security"
},
{
"id": "A.3.16",
"name": "Information security - Compliance with policies, rules and standards for information security"
},
{
"id": "A.3.17",
"name": "Information security - Information security awareness, education and training"
},
{
"id": "A.3.18",
"name": "Information security - Confidentiality or non-disclosure agreements"
},
{
"id": "A.3.19",
"name": "Information security - Clear desk and clear screen"
},
{
"id": "A.3.20",
"name": "Information security - Storage media"
},
{
"id": "A.3.21",
"name": "Information security - Secure disposal or re-use of equipment"
},
{
"id": "A.3.22",
"name": "Information security - User endpoint devices"
},
{
"id": "A.3.23",
"name": "Information security - Secure authentication"
},
{
"id": "A.3.24",
"name": "Information security - Information backup"
},
{
"id": "A.3.25",
"name": "Information security - Logging"
},
{
"id": "A.3.26",
"name": "Information security - Use of cryptography"
},
{
"id": "A.3.27",
"name": "Information security - Secure development life cycle"
},
{
"id": "A.3.28",
"name": "Information security - Application security requirements"
},
{
"id": "A.3.29",
"name": "Information security - Secure system architecture and engineering principles"
},
{
"id": "A.3.30",
"name": "Information security - Outsourced development"
},
{
"id": "A.3.31",
"name": "Information security - Test information"
}
]
}